Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f848-r5g6-6gpf

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Dolibarr Stored Cross-site Scripting

The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

Пакеты

Наименование

dolibarr/dolibarr

composer
Затронутые версииВерсия исправления

= 11.0.4

Отсутствует

EPSS

Процентиль: 38%
0.00169
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-276
CWE-668
CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 5 лет назад

The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

CVSS3: 5.4
nvd
больше 5 лет назад

The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

CVSS3: 5.4
debian
больше 5 лет назад

The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup doc ...

EPSS

Процентиль: 38%
0.00169
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-276
CWE-668
CWE-79